hostcloak.com · terms
Effective 1 September 2026 · HostCloak · hostcloak.com · not legal advice
These terms describe how HostCloak is offered today. They are operator rules, not a pentest engagement letter and not a compliance certificate.
HostCloak is a calm flight deck for solo operators: a defensive posture grade, a prioritized fix order, and (later) live host metrics on machines you name.
It is not a penetration test, not an exploit kit, and not a “how to break in” report. A grade is not a compliance certificate — not PCI, not SOC 2, not an audit letter.
Findings are presence, misconfiguration, and hygiene plus a harden order. You remain responsible for patching, backups, and who can log in.
You may only name a DNS name or IP that you own or for which you have written authorization to assess. By submitting a target you represent that you have that ownership or written authorization.
Unauthorized access to computers is illegal under U.S. law, including the Computer Fraud and Abuse Act (CFAA), and similar laws in other jurisdictions. Scanning a system you do not control, without written permission, is out of scope. HostCloak will not help you do it.
See the Acceptable Use Policy for the scanning rules. Material AUP breaches are grounds for immediate account closure.
We never ask for a root password, sudo password, or SSH private key. Hosts have no password field. Do not send secrets meant to log into the scanned machine.
The optional Live Deck agent (later) authenticates with a per-host bearer token, not a shell password.
Today there is no live checkout. Access is a waitlist email to 48e2c64d4df7414b8e8ef31a4a412625@domainsbyproxy.com. Pricing on the product page is intent (Free limited, Pro ~$19/month, Agency ~$49/month), not a binding charge.
When checkout exists it will be Stripe. Until then, joining the waitlist is not a paid subscription.
A HostCloak report is a defensive posture snapshot for operators. It is not a warranty that the host is safe, not a proof of exploitability, and not something you may represent to customers or auditors as PCI, SOC 2, or any other attestation.
Do not rewrite a report into exploit-shaped output or use it to attack any system.
You remain responsible for the account you use, the hosts you name, and whether a suggested change is right for your box. HostCloak is a flight deck, not your sysadmin.
We may refuse a scan, cancel in-flight work, or close an account for AUP breach, unpaid invoices (once billing exists), or misuse of the scanner.
Operator mail: 48e2c64d4df7414b8e8ef31a4a412625@domainsbyproxy.com. Abuse reports: abuse. Canonical site: www.hostcloak.com.